CVE-2019-9649: Coreftp Core FTP

Medium severity, CVSS 5.3. EPSS: 14.5% chance of exploitation in the next 30 days.

An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote attacker can use a directory traversal technique (..\..\) to browse outside the root directory to determine the existence of a file on the operating system, and its last modified date.

Affected products

Published 2019-03-22. Last modified 2026-06-17.